Live data from Hacker News

Linode hacked, CCs and passwords leaked

slashdot.org

341–350 of 418 posts

Re: Linode hacked, CCs and passwords leaked

#341

Is this why Linode doubled the RAM? To bribe us and make us stay. I'm pretty pissed off about this and will be exploring other options. I'm not pissed off they got hacked, I'm pissed off they are hiding and not being forth coming about it. A simple, "We fucked up, we are going to take steps 1, 2 3 to fix it and reduce the likely hood of this ever happening again" will make me happy. I understand that any server can b…

I'm stunned that you, and plenty of other people in this thread, are taking the anonymous IRC person's word as the gospel truth.

I am not sure that "gospel truth" is a fair characterization.

Anonymous IRC person has provided verifiable details that strongly suggest he or she had access to Linode administrative systems. Fyodor's post to nmap-dev supports the notion that customer nodes were accessed as well.

Linode has provided no details or evidence of anything.

I don't think one has to take that IRC log as gospel truth to be reasonably concerned about the security of their data stored by Linode.

Re: Linode hacked, CCs and passwords leaked

#342

Earlier quoted context omitted.

Until they're hacked, too...

Or until they let other customers see all the data on VMs that you've shut down. Oh wait, that already happened: http://www.wired.com/wiredenterprise/2013/04/digitalocean/

Fuck it, I'm gonna recruit 7 friends and we'll set up our own VM cluster.

Re: Linode hacked, CCs and passwords leaked

#343

Earlier quoted context omitted.

"because it'll be easier to just spend half an hour doing this instead of spending hours upon hours disputing specific transactions." I live on the internet. Put my credit card out on many services. Over the last 5 to 8 years I've had my credit card numbers taken I believe 4 times. Never had to dispute it once. These Credit Card companies and Banks have a stake in not allowing your account to be drained. I think it w…

Wow, four times? You should probably be more careful about who you give your number to. Personally, I usually get a new card every 3-5 months. If someone ever sat on my card number, it's useless to them now. Never had any issues either.

I also do that, but it's because I'm scared of recurring subscriptions that I've forgotten about, especially those that decide to sneak into my pocket after I've deliberately canceled them.

Re: Linode hacked, CCs and passwords leaked

#344

Earlier quoted context omitted.

"because it'll be easier to just spend half an hour doing this instead of spending hours upon hours disputing specific transactions." I live on the internet. Put my credit card out on many services. Over the last 5 to 8 years I've had my credit card numbers taken I believe 4 times. Never had to dispute it once. These Credit Card companies and Banks have a stake in not allowing your account to be drained. I think it w…

Wow, four times? You should probably be more careful about who you give your number to. Personally, I usually get a new card every 3-5 months. If someone ever sat on my card number, it's useless to them now. Never had any issues either.

This is bad for your credit report I believe.

Re: Linode hacked, CCs and passwords leaked

#345

Earlier quoted context omitted.

"because it'll be easier to just spend half an hour doing this instead of spending hours upon hours disputing specific transactions." I live on the internet. Put my credit card out on many services. Over the last 5 to 8 years I've had my credit card numbers taken I believe 4 times. Never had to dispute it once. These Credit Card companies and Banks have a stake in not allowing your account to be drained. I think it w…

Wow, four times? You should probably be more careful about who you give your number to. Personally, I usually get a new card every 3-5 months. If someone ever sat on my card number, it's useless to them now. Never had any issues either.

@kansface It's not bad for your credit rating. A number is simply a representation of the account. The account doesn't change. It's not like getting a whole new item of credit issued. Just the means to access it.

Also, great idea. But a pain, because most of my bills - cell, internet, insurance(s), etc all go through my credit cards. Is a gigantic pain to change the numbers.

Re: Linode hacked, CCs and passwords leaked

#346
post #341

Earlier quoted context omitted.

I'm stunned that you, and plenty of other people in this thread, are taking the anonymous IRC person's word as the gospel truth.

I am not sure that "gospel truth" is a fair characterization. Anonymous IRC person has provided verifiable details that strongly suggest he or she had access to Linode administrative systems. Fyodor's post to nmap-dev supports the notion that customer nodes were accessed as well. Linode has provided no details or evidence of anything. I don't think one has to take that IRC log as gospel truth to be reasonably concern…

The only "verifiable detail" I saw in the chatlog was the output of `ls` in the http root. And that's only verifiable because you can try to access that weirdly-named HTML file and get a 200 back. Honestly, that doesn't tell me a whole lot.

Everything else, such as the password hashes, don't seem at all verifiable (even if someone were to crack any of the hashes, you can't verify that the password worked at the time of the hack because Linode has presumably changed them all anyway).

Re: Linode hacked, CCs and passwords leaked

#347
post #89
post #36

Earlier quoted context omitted.

Here is what Linode replied to me when I asked them about that chat log in a support ticket: Hello, Thank you for reaching out. We appreciate and understand your concerns. At this time the evidence suggest that this activity was targeting a specific customer. We are unable to release any additional details regarding this incident at this time, as there is an ongoing investigation. We have no comment regarding ryan*'s…

These guys are looking totally incompetent at this point. If you believe this Ryan guy, credit cards stored on the same server as the key to decrypt them, Lish passwords stored in plain text, they've known for some time and lied about what actually happened and now they're saying "we won't do anything about it" via email? "You are of course free to take any steps you deem prudent or necessary to ensure the integrity…

> If you believe this Ryan guy

That's a rather key assumption. If you don't believe him, then all you have is a trolling (or at least self-aggrandizing) hacker whose credentials consist solely of logging into an IRC channel, refusing to identify who he was working with, and offering no tangible proof of having compromised any CC info.

On the other hand, it's conceivable that if ryan managed to get into the files a customer was hosting on Linode, and that customer was improperly storing CC info, then their customers' info would have been vulnerable, and ryan's claims would be sort of half-true. Even so, that wouldn't directly affect other Linode customers or put liability in Linode's lap.

Re: Linode hacked, CCs and passwords leaked

#348
This is disappointing and scary. A friend on another forum posted that some guy on IRC told him the last 4 digits of his CC and his e-mail address. I just called my bank and cancelled my current CC and give me a new number. I really liked Linode too :(

Re: Linode hacked, CCs and passwords leaked

#349

Earlier quoted context omitted.

Wow, four times? You should probably be more careful about who you give your number to. Personally, I usually get a new card every 3-5 months. If someone ever sat on my card number, it's useless to them now. Never had any issues either.

This is bad for your credit report I believe.

He's not tearing down and setting back up the entire credit line, just the card number associated with it. It won't be reflected on any credit reports.

Re: Linode hacked, CCs and passwords leaked

#350
If this is indeed true I will be very disappointed, I have had an otherwise great relationship with Linode.

I await for more data and hopefully an official response from Linode.

If the worst case is true, what are some good alternatives for Linux VPS hosting?

Post reply on HN